Re: [TLS] Comparative cipher suite strengths
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Comparative cipher suite strengths



Eric,

Are you saying that 2^128 computations will never be feasible, and therefore, that Moore's law will stop?

Best regards,

	Dan

-----Original Message-----
From: Eric Rescorla
Sent: Wednesday, April 22, 2009 9:46 AM
To: Blumenthal, Uri
Cc: 'tls at ietf.org'
Subject: Re: [TLS] Comparative cipher suite strengths

The amount of computational power required to break a 128-bit AES
key with current is so outlandishly large that there is plausible
scenario that such a key will be broken by brute force. The 
only plausible situations in which 128-bit AES keys are breakable,
then, are non-brute-force attacks such as attacks on the implementation
or an analytic attack. In neither case does 2^{128} represent
an accurate estimate of the security of the algorithm, nor is
there any reason to believe that AES-256 is 2^{128} times more
secure under such attacks. Thus, the inference that one ought to
use an RSA key that is 2^{128} times stronger with AES-256 than
AES-128 also does not follow.


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.